Technical Description: Nixu Registry Server

Size: px
Start display at page:

Download "Technical Description: Nixu Registry Server"

Transcription

1 Technical Description: Nixu Registry Server Nixu Software Oy Ltd A Nixu Group Company Keilaranta 15 FI Espoo Finland 1

2 1. Overview of Nixu Registry Server Nixu Registry Server is a Domain Name Registry Solution (DNRS) developed for generic and mid-sized Top-Level Domains (TLDs). Designed as a solution framework with modular architecture, Nixu Registry Server can be configured and tailored on perinstallation basis to meet the exact requirements of the customer. The configurable modules in Nixu Registry Server include: Web-based domain reservation portal for the registry operators Web-based self-service domain reservation portal for end-users Web-based API for dynamic integration with registrars (toolkits on request) WHOIS server with data replicator Domain accounting and billing integration module Domain checking and network tools available to end-users Choice between external or embedded SQL backend Support for agents of commonly used OSS and back-up systems Nixu Registry Server comes with a number of reservation process automations, allowing registries running Nixu solution to provide a self-service reservation portal to the endusers, and a web-based API for its registrars. The underlying AJAX-based web framework and a built-in IDN support enable the localization of both look & feel and used languages, to align with the local business environment. To automate the related business processes and requirements, Nixu Registry Server supports various, configurable domain accounting rules and can be integrated with virtually any billing and/or other backend systems. Depending on the project scope, Nixu Registry Server is delivered either as a highlyavailable standalone DNRS integrated with existing Domain Name System (DNS) primary platform, or as a part of a complete end-to-end DNRS & DNS Infrastructure turnkey delivery. The DNS part of a turnkey delivery can consist of: 1. Proprietary Nixu DNS Primary platform (Nixu NameSurfer Suite) integrated with existing DNS secondaries. In this scenario, the supported DNS secondary types include Nixu SNS, Secure64 DNS, BIND and NSD. Also other RFC-compliant DNS secondary types are supported; however, these remote servers and/or services cannot be controlled remotely from Nixu NameSurfer Suite. 2. Proprietary Nixu DNS Primary platform coupled with new DNS secondaries. Nixu can deliver either Nixu SNS (BIND-based), Secure64 DNS (NSD-based), BIND or NSD secondary servers. 3. A mixed delivery consisting of proprietary Nixu DNS Primary platform, new DNS secondaries and existing DNS secondaries and/or secondary services. Nixu NameSurfer Suite used as the proprietary DNS Primary platform is the marketleading DDI solution used by Fortune 500 companies; more than 30 percent of all 2.5G (GPRS) and 3G (UMTS) service providers; and five Top-Level Domains worldwide. It has been designed for secure, centralized management of organizations' DNS data and IP address space, and can also be used for centralized management of remote DNS servers. Thanks to its proprietary DNS primary server process and powerful networkbased API, it can be easily integrated with external applications and services, making Nixu NameSurfer Suite the DDI provisioning platform of choice 2

3 2. Deployment Descriptions and Recommendations To achieve six-sigma availability in the deployment, Nixu recommends that both the DNRS (Nixu Registry Server) and the primary DNS (Nixu NameSurfer) platforms be deployed as highly available server pairs over two data centres, each with two network links and redundant load-balancer(s). With this deployment strategy, every component used in the installation is doubled, making sure that even if any one part of the solution or indeed the entire data centre failed, the operations would continue uninterrupted. As far as the secondary DNS service is concerned, Nixu recommends the following approach: 1. For each DNS secondary node, one or two authoritative DNS secondary server instances should be run in both data centres. These servers would be run as a single secondary DNS cluster node behind a single public IP, utilizing either the load-balancers described in paragraph 1 or anycast technique. The exact number of secondary servers assigned to each node (two/four/more) depends on the level of performance and redundancy the TLD expects to achieve. Especially in situations where the companies operating local DNS secondary clusters do not have a data centre in the TLDs country of origin, this approach can be used to ensure that the public DNS service will continue to run uninterrupted even if the network connections to the overseas data centre / service provider were disconnected for any reason. 2. The secondary DNS server node(s) should ideally be complemented by running anycasted secondary DNS service procured from a specialist company operating such service. Nixu has relations with such companies and will be happy to make recommendations upon request. Below, please find a diagram describing the solution architecture recommended by Nixu: 3

4 Below, please find an overview of the roles of the different servers used in the installations. The roles of these servers are assigned as follows: Server 1: Server 2: Server 3: Server 4: Web-Proxy: Nixu Registry Server running on native x86-based hardware on Site A Nixu Registry Server running on native x86-based hardware on Site B Nixu NameSurfer Suite (DNS Primary) running on native x86-based hardware on Site A Nixu NameSurfer Suite (DNS Primary) running on native x86-based hardware on Site B The web-proxy running in front of Sites A and B in the diagram should be interpreted as a highly available proxy cluster. Server 1 Server 1 runs Nixu Registry Server. This server is used for self-service domain reservations and modifications as well as related tasks such as domain availability searches and DNS diagnostics (either universal or cctld / gtld specific); to provide the registry staff with an administrative interface for the management of reserved domains and domain reservations; to push the reserved and/or amended domain information to the primary DNS platform; to generate the billing tickets required by the online payment service provider; and to provide the WHOIS service for the gtld/cctld and possible subdomains. The embedded SQL backend is either an embedded Postgres db or an external Oracle db, and the contents of the databases are replicated between Servers 1 and 2. The network-based API included in the Nixu Registry Server supports EPP and can be used by registrars to automate the domain reservation processes between their own systems and the registry. Server 2 Identical to Server 1. In order to make sure that the service provided by servers 1 and 2 shall be fault-tolerant and transparent to the end-user, these two servers shall be run in active-active or active-standby mode behind two load-balancers both of which advertise the same IP address, sharing load between the servers, and directing traffic to the remaining server in the event that either one of the servers fail for any reason. Below, please find a process diagram depicting the related domain reservation process: 4

5 Server 3 Server 3 runs Nixu NameSurfer Suite. This server is used as the hidden DNS primary server supporting IPv4, IPv6, DNSSEC, ENUM and IDN. This server is integrated with Servers 1 and 2 over a network-based API (XML-RPC) included in the product, allowing dynamic updates to master zone file(s) from servers 1 and 2. Whenever changes to the zone file are made, Nixu NameSurfer Suite pushes those changes automatically to the secondary DNS servers using Incremental Zone Transfers (IXFR; please note, also AXFR is supported). The configurations of the secondary DNS services controlled by the Registry can be managed centrally using Nixu NameSurfer s Remote Servers management utility. Furthermore, in addition to obtaining changes pertaining to the domain information from Servers 1 and 2, Nixu NameSurfer Suite also automates the DNS management tasks for the zones the Registry is authoritative for including creation of reverse entries and zone serial numbering. The server includes network-based API and command-line interface, and a web-based user-interface and User Groups functionality that can be used to provide a SSL secured connection to all DNS master data. The User Groups functionality includes an audit trail listing the WHO, WHAT and WHEN of any and all DNS changes made using the system, coupled with a convenient undo/redo functionality that can be used to reverse undesired changes. The collection period used in connection with the audit trail can be freely defined according to the policy requirements of the enduser organization. To assure the integrity and the security of the deployment, the proprietary primary DNS server is deployed as hidden primary, i.e. it will not be visible to the outside world, except for the secondary DNS servers to which connections are encrypted using SSH and authenticated using transaction signatures (TSIGs). Thanks to its embedded SQL backend (Solid EmbeddedEngine by IBM), the hidden primary DNS server is capable of serving tens of millions of objects in its database when run on industry-standard hardware such as HP ProLiant Series. Since the SQL backend is embedded, no network traffic occurs between the DNS primary and external backends, thereby mitigating the possibility of data interception. Server 4 Identical to server 3. The two hidden DNS primary servers in the installation (Servers 3 and 4) store all data in embedded SQL backends, and are run in active-passive mode. In other words, the active primary DNS server is used for all management routines and to obtain dynamic changes to DNS made using the API or dyndns. Thanks to the hotstandby replication technology used in these servers, all changes made using the active primary are propagated in real-time to the SQL backend of the hot-standby replica, making the two servers identical at all times. In the event that the active server goes offline for a pre-defined period of time, watchdog software included in the delivery appoints the hot-standby replica as the new active primary, and the web-proxy on the servers starts forwarding users to the newly appointed active primary. Please note that in addition to hot-standby replication, the servers also support online back-ups of the configurations and the database, using simple CLI command coupled with utilities such as cron. Below, please find a diagram depicting the relationship between Nixu NameSurfer Suite primary server and the possible secondary DNS servers used in the deployment: 5

6 Web- Proxy While the Web-Proxy included in the diagram on page 3 is depicted as a single machine, it represents a web-proxy / load-balancing cluster consisting of a number of machines split over two data centres, advertising a single public IP address for the services running on servers 1, 2, 3 and 4. Upon request, Nixu will be happy to make recommendations on proxy / load-balancing products suitable for this purpose. Secondary DNS Service The clustered (anycasted / load-balanced) secondary DNS nodes used in connection with Nixu delivery can be implemented using Nixu SNS (BIND-based), Secure64 DNS Authority (NSD based), BIND or NSD. The recommended deployment would consist of different DNS server types (either NSD or BIND based), increasing the resistance to DNS server software vulnerabilities that could be found in any single DNS server type. In addition to the clustered DNS secondary nodes dedicated to a single cctld / gtld, also globally distributed secondary DNS services can be used in connection with the Nixu solution. Below, please find a brief description of Nixu SNS (Secure Name Server) would be used in this context. Nixu SNS is run as a secondary DNS server authoritative for the cctld / gtld zone(s) and possible subdomains. The product supports all relevant RFCs pertaining to IPv6, DNSSEC, IDN and ENUM. Nixu SNS is a hardened, BIND-based purpose-built DNS server with Intrusion Detection / Intrusion Prevention system used to mitigate DDoS and similar attacks. While the scalability of Nixu SNS depends on the hardware platform it is being run on, a Nixu SNS server instances running on an industry-standard HP ProLiant DL360 or similar server is capable of answering more than 30,000 queries per second. 6

7 When deployed as a clustered node, four servers such as this running behind a single public IP are capable of answering more than 120,000 per second per clustered node. To ensure their security, Nixu SNS servers are configured so that their configurations can be managed remotely from the DNS primary using SSH and SCP, and the zone transfers from primary DNS server are performed over a SSH secured connection using TSIG authentication. The DNS secondary servers support automated software updates that allow automated patching of the server software whenever new vulnerabilities are discovered. Integration The integration between Nixu Registry Server and Nixu NameSurfer Suite (Primary DNS Service) is carried out using a network-based APIs included in the products. In the event that an existing Primary DNS Platform is used, Nixu Registry Server can be integrated against the published API of that system. The integration between Nixu NameSurfer Suite and the secondary DNS servers / services would be carried out and secured using RFC-based standards such as zone transfers (IXFR/AXFR), NOTIFY, transaction signatures (TSIGs), SSH and SCP. When running Nixu SNS and/or Secure64 DNS Authority in the deployment, both servers come with built-in support for remote & centralized management from Nixu NameSurfer s Remote Servers management utility. The integration between the payment gateway and Nixu Registry Server is performed using a network-based API. This same API would also be used in communications between the Registry and Registrars. 7

8 3. About Nixu Software Nixu Software is an affiliate of privately held Nixu Group founded in Headquartered in Helsinki, Finland, and with number of regional sales offices in Europe, the Americas and Asia Pacific, our mission is to offer the best value for money within the DNS and IP addressing industry. The execution of our mission is based on our DNS, DHCP and IP address management solutions and software appliances that set the benchmark for combined security, ease of use, and low cost of ownership. Nixu Software leverages Nixu Group's world-class expertise in software development and information security by developing secure DNS and IP address management solutions and software appliances. Our products can be deployed either as standalone end-to-end solutions, or as components of more extensive turnkey solutions developed in co-operation with different OEMs. Nixu Software stresses four fundamentals in all its product development efforts: security, scalability, availability and efficiency. Having longstanding blue-chip customers who have managed 100% DNS uptime for a decade while reducing the related management costs by more than 50% per year, our track record is second to none. Nixu Software's DNS products have an installed base consisting of more than server instances worldwide. Our technologies are used by more than 30% of all 2.5G and 3G mobile operators globally; dozens of Fortune 500 companies; and several generic and country code Top Level Domains in Europe and Asia Pacific. 8

Integrating Nixu IPAM with Microsoft AD. White Paper January 2011

Integrating Nixu IPAM with Microsoft AD. White Paper January 2011 Integrating Nixu IPAM with Microsoft AD White Paper January 2011 DNS, DHCP and IP Address Management (IPAM) in Microsoft AD Environments Organizations running Microsoft DNS and DHCP services have traditionally

More information

IPAM for Enterprise Environment

IPAM for Enterprise Environment IPAM for Enterprise Environment Introducing Nixu NameSurfer White Paper by FusionLayer,Inc. October 2011 Copyright 2015 FusionLayer, Inc. All rights reserved. No part of this publication may be reproduced,

More information

Integrating FusionLayer IPAM with Microsoft AD. A White Paper by FusionLayer

Integrating FusionLayer IPAM with Microsoft AD. A White Paper by FusionLayer Integrating FusionLayer IPAM with Microsoft AD A White Paper by FusionLayer June 2012 Copyright 2015 FusionLayer, Inc. All rights reserved. No part of this publication may be reproduced, stored in a retrieval

More information

Virtualized Domain Name System & IP Addressing Environments. White Paper by FusionLayer, Inc.

Virtualized Domain Name System & IP Addressing Environments. White Paper by FusionLayer, Inc. Virtualized Domain Name System & IP Addressing Environments White Paper by FusionLayer, Inc. September 2016 Copyright 2018 FusionLayer, Inc. All rights reserved. No part of this publication may be reproduced,

More information

Integrating FusionLayer Infinity With Microsoft AD. A White Paper by FusionLayer Inc.

Integrating FusionLayer Infinity With Microsoft AD. A White Paper by FusionLayer Inc. Integrating FusionLayer Infinity With Microsoft AD A White Paper by FusionLayer Inc. June 2018 Copyright 2018 FusionLayer Inc. All rights reserved. No part of this publication may be reproduced, stored

More information

A Better Way to a Redundant DNS.

A Better Way to a Redundant DNS. WHITEPAPE R A Better Way to a Redundant DNS. +1.855.GET.NSONE (6766) NS1.COM 2019.02.12 Executive Summary DNS is a mission critical application for every online business. In the words of Gartner If external

More information

USING TRANSACTION SIGNATURES (TSIG) FOR SECURE DNS SERVER COMMUNICATION

USING TRANSACTION SIGNATURES (TSIG) FOR SECURE DNS SERVER COMMUNICATION USING TRANSACTION SIGNATURES (TSIG) FOR SECURE DNS SERVER COMMUNICATION 11-30-2016 USING TRANSACTION SIGNATURES (TSIG) FOR SECURE DNS SERVER COMMUNICATION Transaction Signatures (TSIG) provide a secure

More information

Cloud Operations for Oracle Cloud Machine ORACLE WHITE PAPER MARCH 2017

Cloud Operations for Oracle Cloud Machine ORACLE WHITE PAPER MARCH 2017 Cloud Operations for Oracle Cloud Machine ORACLE WHITE PAPER MARCH 2017 Disclaimer The following is intended to outline our general product direction. It is intended for information purposes only, and

More information

IBM Tivoli Directory Server

IBM Tivoli Directory Server Build a powerful, security-rich data foundation for enterprise identity management IBM Tivoli Directory Server Highlights Support hundreds of millions of entries by leveraging advanced reliability and

More information

SCALEFAST COMMERCE CLOUD INFRASTRUCTURE

SCALEFAST COMMERCE CLOUD INFRASTRUCTURE SCALEFAST COMMERCE CLOUD INFRASTRUCTURE ALWAYS-ON, GLOBAL ECOMMERCE INFRASTRUCTURE Scalefast provides the highest level of availability, performance and security for your online store. We take care of

More information

All about.au. Chris Wright CTO AusRegistry International ICANN no. 35, Sydney, Australia 22 nd June 2009

All about.au. Chris Wright CTO AusRegistry International ICANN no. 35, Sydney, Australia 22 nd June 2009 All about.au Chris Wright CTO AusRegistry International ICANN no. 35, Sydney, Australia 22 nd June 2009 AusRegistry International Located in Melbourne, Australia Involved in Domain Name Industry since

More information

BEST PRACTICES FOR IMPROVING EXTERNAL DNS RESILIENCY AND PERFORMANCE

BEST PRACTICES FOR IMPROVING EXTERNAL DNS RESILIENCY AND PERFORMANCE BEST PRACTICES FOR IMPROVING EXTERNAL DNS RESILIENCY AND PERFORMANCE 12-07-2016 BEST PRACTICES FOR IMPROVING EXTERNAL DNS RESILIENCY AND PERFORMANCE Your external DNS is a mission critical business resource.

More information

BMC Remedyforce Discovery and Client Management. Frequently asked questions

BMC Remedyforce Discovery and Client Management. Frequently asked questions BMC Remedyforce Discovery and Client Management Frequently asked questions 1 Table of Contents BMC Remedyforce Discovery and Client Management 4 Overview 4 Remedyforce Agentless Discovery 4 Remedyforce

More information

DNS SECURITY BEST PRACTICES

DNS SECURITY BEST PRACTICES White Paper DNS SECURITY BEST PRACTICES Highlights Have alternative name server software ready to use Keep your name server software up-to-date Use DNSSEC-compliant and TSIG-compliant name server software

More information

In the Domain Name System s language, rcode 0 stands for: no error condition.

In the Domain Name System s language, rcode 0 stands for: no error condition. 12/2017 SIMPLE, FAST, RESILIENT In the Domain Name System s language, rcode 0 stands for: no error condition. If a DNS server answers a query with this result code, the service is running properly. This

More information

Copyright 2011 Nomadix, Inc. All Rights Reserved Agoura Road Suite 102 Agoura Hills CA USA White Paper

Copyright 2011 Nomadix, Inc. All Rights Reserved Agoura Road Suite 102 Agoura Hills CA USA   White Paper Nomadix Service Engine Access in Large Public Venues Copyright 2011 Nomadix, Inc. All Rights Reserved. 30851 Agoura Road Suite 102 Agoura Hills CA 91301 USA www.nomadix.com 230-1026-001 Sheet 2 of 9 Introduction

More information

Draft Applicant Guidebook, v3

Draft Applicant Guidebook, v3 Draft Applicant Guidebook, v3 Module 5 Please note that this is a discussion draft only. Potential applicants should not rely on any of the proposed details of the new gtld program as the program remains

More information

Etisalat DNS. Internet Core Services. By Mohamed Albanna. Manager/ Internet Core Services

Etisalat DNS. Internet Core Services. By Mohamed Albanna. Manager/ Internet Core Services Etisalat DNS Internet Core Services By Mohamed Albanna Manager/ Internet Core Services Outline 1. Introduction 2. DNS setup (1996-2015) 3. Challenges 4. DNS Modernization Plan (2015 2017) 5. Performance

More information

Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03

Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03 Factsheet of Public Services Infrastructure (PSi) Updated on: 1st Sep 03 1 Objective of Paper 1.1 This document provides an overview of the Public Services Infrastructure (PSi). 2 Overview of PSi 2.1 PSi

More information

Harness Your Internet Activity

Harness Your Internet Activity Harness Your Internet Activity Enabling Efficiency and Service Differentiation Ralf Weber October 13, 2014 Authoritative DNS Proven High-performance Tested with up to 1 Billion resource records per server

More information

IBM Secure Proxy. Advanced edge security for your multienterprise. Secure your network at the edge. Highlights

IBM Secure Proxy. Advanced edge security for your multienterprise. Secure your network at the edge. Highlights IBM Secure Proxy Advanced edge security for your multienterprise data exchanges Highlights Enables trusted businessto-business transactions and data exchange Protects your brand reputation by reducing

More information

AfriNIC 14 Shared cctld DNSSEC Signing Platform June 9, 2011 Bill Woodcock Research Director Packet Clearing House

AfriNIC 14 Shared cctld DNSSEC Signing Platform June 9, 2011 Bill Woodcock Research Director Packet Clearing House AfriNIC 14 Shared cctld DNSSEC Signing Platform June 9, 2011 Bill Woodcock Research Director Packet Clearing House ICANN - Common Goals ICANN Goals: Accelerate DNSSEC deployment Maintain the highest standards

More information

The F5 Intelligent DNS Scale Reference Architecture

The F5 Intelligent DNS Scale Reference Architecture The F5 Intelligent DNS Scale Reference Architecture End-to-end DNS delivery solutions from F5 maximize the use of organizational resources, while remaining agile and intelligent enough to scale and support

More information

Shared cctld DNSSEC Signing Platform Bill Woodcock and Rick Lamb ICANN San Francisco March 2011

Shared cctld DNSSEC Signing Platform Bill Woodcock and Rick Lamb ICANN San Francisco March 2011 Shared cctld DNSSEC Signing Platform Bill Woodcock and Rick Lamb ICANN San Francisco March 2011 ICANN - Common Goals ICANN Goals: Accelerate DNSSEC deployment Maintain the highest standards of security

More information

BIG-IP DNS Services: Implementations. Version 12.0

BIG-IP DNS Services: Implementations. Version 12.0 BIG-IP DNS Services: Implementations Version 12.0 Table of Contents Table of Contents Configuring DNS Express...11 What is DNS Express?...11 About configuring DNS Express...11 Configuring DNS Express

More information

Document Sub Title. Yotpo. Technical Overview 07/18/ Yotpo

Document Sub Title. Yotpo. Technical Overview 07/18/ Yotpo Document Sub Title Yotpo Technical Overview 07/18/2016 2015 Yotpo Contents Introduction... 3 Yotpo Architecture... 4 Yotpo Back Office (or B2B)... 4 Yotpo On-Site Presence... 4 Technologies... 5 Real-Time

More information

Running the Setup Web UI

Running the Setup Web UI The Cisco Prime IP Express setup interview in the web UI takes you through a series of consecutive pages to set up a basic configuration. For an introduction and details on the basic navigation for the

More information

How-to Guide: Tenable.io for Microsoft Azure. Last Updated: November 16, 2018

How-to Guide: Tenable.io for Microsoft Azure. Last Updated: November 16, 2018 How-to Guide: Tenable.io for Microsoft Azure Last Updated: November 16, 2018 Table of Contents How-to Guide: Tenable.io for Microsoft Azure 1 Introduction 3 Auditing the Microsoft Azure Cloud Environment

More information

cctld Best Practices & Considerations John Crain Internet Corporation for Assigned Names and Numbers

cctld Best Practices & Considerations John Crain Internet Corporation for Assigned Names and Numbers cctld Best Practices & Considerations John Crain Internet Corporation for Assigned Names and Numbers cctld as a public trust cctlds are designated to operators who will operate them in the best interests

More information

BIG-IP DNS Services: Implementations. Version 12.1

BIG-IP DNS Services: Implementations. Version 12.1 BIG-IP DNS Services: Implementations Version 12.1 Table of Contents Table of Contents Configuring DNS Express...9 What is DNS Express?...9 About configuring DNS Express...9 Configuring DNS Express to

More information

CogniFit Technical Security Details

CogniFit Technical Security Details Security Details CogniFit Technical Security Details CogniFit 2018 Table of Contents 1. Security 1.1 Servers........................ 3 1.2 Databases............................3 1.3 Network configuration......................

More information

How-to Guide: Tenable Nessus for Microsoft Azure. Last Updated: April 03, 2018

How-to Guide: Tenable Nessus for Microsoft Azure. Last Updated: April 03, 2018 How-to Guide: Tenable Nessus for Microsoft Azure Last Updated: April 03, 2018 Table of Contents How-to Guide: Tenable Nessus for Microsoft Azure 1 Introduction 3 Auditing the Microsoft Azure Cloud Environment

More information

INNOVATIVE SD-WAN TECHNOLOGY

INNOVATIVE SD-WAN TECHNOLOGY INNOVATIVE SD-WAN TECHNOLOGY Enhance network performance and increase ROI with WANworX TM Many of the WAN deployments today are based on older technology that was acceptable when businesses did not run

More information

Network. Arcstar Universal One

Network. Arcstar Universal One Network Universal One ARCSTAR UNIVERSAL ONE Universal One Enterprise Network NTT Communications' Universal One is a highly reliable, premium-quality network service, delivered and operated in more than

More information

DNSSEC en.mx. Network Information Center México

DNSSEC en.mx. Network Information Center México DNSSEC en.mx Network Information Center México 2 Agenda 1. About NIC México 2..mx DNSSEC test bed 3. Education about DNSSEC 4. NSEC zone walking 3 About NIC México cctld operator of.mx (México). National

More information

DNS Security. Wolfgang Nagele DNS Services Manager

DNS Security. Wolfgang Nagele DNS Services Manager DNS Security Wolfgang Nagele DNS Services Manager DNS: the Domain Name System Specified by Paul Mockapetris in 1983 Distributed Hierarchical Database Main purpose: Translate names to IP addresses Since

More information

Total Cost of Ownership: Database Software and Support

Total Cost of Ownership: Database Software and Support Total Cost of Ownership: Database Software and Support WHITE PAPER MariaDB TX vs. Oracle Database Enterprise Edition AUGUST 08 Table of Contents Executive Summary - MariaDB TX - Market - Analysis Enterprise

More information

Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management

Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management Solution Overview Cisco Wide Area Application Services: Secure, Scalable, and Simple Central Management What You Will Learn Companies are challenged with conflicting requirements to consolidate costly

More information

LGS INNOVATIONS IP ADDRESS MANAGEMENT

LGS INNOVATIONS IP ADDRESS MANAGEMENT LGS INNOVATIONS IP ADDRESS MANAGEMENT Streamlining Administration for Security and Savings Is your Domain Name System (DNS) getting the attention it deserves? DNS is the hierarchical distributed naming

More information

Microsoft SQL Server on Stratus ftserver Systems

Microsoft SQL Server on Stratus ftserver Systems W H I T E P A P E R Microsoft SQL Server on Stratus ftserver Systems Security, scalability and reliability at its best Uptime that approaches six nines Significant cost savings for your business Only from

More information

Technical Overview. Version March 2018 Author: Vittorio Bertola

Technical Overview. Version March 2018 Author: Vittorio Bertola Technical Overview Version 1.2.3 26 March 2018 Author: Vittorio Bertola vittorio.bertola@open-xchange.com This document is copyrighted by its authors and is released under a CC-BY-ND-3.0 license, which

More information

DNS/DNSSEC Workshop. In Collaboration with APNIC and HKIRC Hong Kong. Champika Wijayatunga Regional Security Engagement Manager Asia Pacific

DNS/DNSSEC Workshop. In Collaboration with APNIC and HKIRC Hong Kong. Champika Wijayatunga Regional Security Engagement Manager Asia Pacific DNS/DNSSEC Workshop In Collaboration with APNIC and HKIRC Hong Kong Champika Wijayatunga Regional Security Engagement Manager Asia Pacific 22-24 January 2018 1 Agenda 1 2 3 Introduction to DNS DNS Features

More information

SECURITY ON AWS 8/3/17. AWS Security Standards MORE. By Max Ellsberry

SECURITY ON AWS 8/3/17. AWS Security Standards MORE. By Max Ellsberry SECURITY ON AWS By Max Ellsberry AWS Security Standards The IT infrastructure that AWS provides has been designed and managed in alignment with the best practices and meets a variety of standards. Below

More information

Integrated DHCP, DNS & IP Address Management

Integrated DHCP, DNS & IP Address Management Integrated DHCP, DNS & IP Address Management. Cisco Prime Network Registrar Charlie Mascari, Product Manager Network Management Technology Group September 2011 2010 Cisco and/or its affiliates. All rights

More information

Corrigendum 3. Tender Number: 10/ dated

Corrigendum 3. Tender Number: 10/ dated (A premier Public Sector Bank) Information Technology Division Head Office, Mangalore Corrigendum 3 Tender Number: 10/2016-17 dated 07.09.2016 for Supply, Installation and Maintenance of Distributed Denial

More information

.BIZ Agreement Appendix 10 Service Level Agreement (SLA) (22 August 2013)

.BIZ Agreement Appendix 10 Service Level Agreement (SLA) (22 August 2013) .BIZ Agreement Appendix 10 Service Level Agreement (SLA) (22 August 2013) Registry Operator and ICANN agree to engage in good faith negotiations to replace this Appendix 10 with a Service Level Agreement

More information

Veritas Storage Foundation for Windows by Symantec

Veritas Storage Foundation for Windows by Symantec Veritas Storage Foundation for Windows by Symantec Advanced online storage management Veritas Storage Foundation 5.0 for Windows brings advanced online storage management to Microsoft Windows Server environments.

More information

DNS Security. Wolfgang Nagele DNS Group Manager

DNS Security. Wolfgang Nagele DNS Group Manager DNS Security Wolfgang Nagele DNS Group Manager DNS: the Domain Name System Specified by Paul Mockapetris in 1983 Distributed Hierarchical Database Main purpose: Translate names to IP addresses Since then:

More information

Root Servers. Root hints file come in many names (db.cache, named.root, named.cache, named.ca) See root-servers.org for more detail

Root Servers. Root hints file come in many names (db.cache, named.root, named.cache, named.ca) See root-servers.org for more detail What is DNS? Systems to convert domain names into ip addresses: For an instance; www.tashicell.com 118.103.136.66 Reverse: 118.103.136.66 www.tashicell.com DNS Hierarchy Root Servers The top of the DNS

More information

Rock-solid Internet infrastructure. (Yeah, we keep our stuff in bunkers.)

Rock-solid Internet infrastructure. (Yeah, we keep our stuff in bunkers.) Rock-solid Internet infrastructure. (Yeah, we keep our stuff in bunkers.) WHO DO YOU TRUST TO GET THE JOB DONE? Innovation at the core of the Internet When it comes to Internet services, you need a partner

More information

Citrix SD-WAN for Optimal Office 365 Connectivity and Performance

Citrix SD-WAN for Optimal Office 365 Connectivity and Performance Solution Brief Citrix SD-WAN for Optimal Office 365 Connectivity and Performance Evolving Needs for WAN Network Architecture Enterprise networks have historically been architected to provide users access

More information

Enterprise Open Source Databases

Enterprise Open Source Databases Enterprise Open Source Databases WHITE PAPER MariaDB vs. Oracle MySQL vs. EnterpriseDB MariaDB TX Born of the community. Raised in the enterprise. MariaDB TX, with a history of proven enterprise reliability

More information

IaaS Buyer s Checklist.

IaaS Buyer s Checklist. Problem Solved IaaS Buyer s Checklist. Yes it s another checklist, but this one s actually useful. 2 Problem Solved Service levels. Does the provider offer your required SLA/SLG? Example: 99.9%, 99.95%,100%

More information

Instructions for PDT testing

Instructions for PDT testing Instructions for PDT testing Version: 1.5 Update 1 16 May 2013 1 Introduction... 2 1.1 Methodology... 2 1.2 Data entry into the PDT System... 2 2 PDT Test Nodes... 2 2.1 IP addresses... 3 3 DNS test...

More information

FRED open source registry solution. Jaromir Talir

FRED open source registry solution. Jaromir Talir FRED open source registry solution Jaromir Talir jaromir.talir@nic.cz Agenda CZ.NIC story FRED overview Deployments Data model Interfaces Features CZ.NIC story - year 2005 CZ.NIC had 4 employees Number

More information

Infrastructure as a Service (IaaS) Compute with Storage and Backup PRICING DOCUMENT

Infrastructure as a Service (IaaS) Compute with Storage and Backup PRICING DOCUMENT Infrastructure as a Service (IaaS) Compute with Storage and Backup PRICING DOCUMENT Contents 1 Cloud+ IaaS Pricing...2 1.1 Service Pricing Guide... Error! Bookmark not defined. 1.2 Cloud+ Networking Pricing...

More information

Domain Registrations. Shared Hosting. Office 365 and Hosted Exchange #DOMAINS #HOSTING #

Domain Registrations. Shared Hosting. Office 365 and Hosted Exchange #DOMAINS #HOSTING # GDPR Compliance Responsibilities on Blacknight Products April 2018 GDPR is due to come into force May 25 th 2018. It sets out regulations for security and privacy controls required when handling Personally

More information

Keeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson

Keeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson Keeping DNS parents and children in sync at Internet Speed! Ólafur Guðmundsson olafur@cloudflare.com How long does it take to? Post a new selfie on Facebook and all your friends to be notified few seconds

More information

Identity Firewall. About the Identity Firewall

Identity Firewall. About the Identity Firewall This chapter describes how to configure the ASA for the. About the, on page 1 Guidelines for the, on page 7 Prerequisites for the, on page 9 Configure the, on page 10 Monitoring the, on page 16 History

More information

(Towards) a Threshold Cryptographic Backend for DNSSEC

(Towards) a Threshold Cryptographic Backend for DNSSEC (Towards) a Threshold Cryptographic Backend for DNSSEC OARC 2011 Antonio Cansado acansado@niclabs.cl Pablo Sepúlveda psepulv@niclabs.cl Tomás Barros tbarros@niclabs.cl Victor Ramiro vramiro@niclabs.cl

More information

OpenIAM Identity and Access Manager Technical Architecture Overview

OpenIAM Identity and Access Manager Technical Architecture Overview OpenIAM Identity and Access Manager Technical Architecture Overview Overview... 3 Architecture... 3 Common Use Case Description... 3 Identity and Access Middleware... 5 Enterprise Service Bus (ESB)...

More information

A White Paper on VeriSign Managed DNS Services

A White Paper on VeriSign Managed DNS Services Prepared By: 21345 Ridgetop Circle Dulles, VA 166 1.3.948.30 A White Paper on VeriSign Managed DNS Services November 01 Introduction VeriSign Secondary Name Server Hosting If your business depends on the

More information

Virtual Private Networks (VPNs)

Virtual Private Networks (VPNs) CHAPTER 19 Virtual Private Networks (VPNs) Virtual private network is defined as customer connectivity deployed on a shared infrastructure with the same policies as a private network. The shared infrastructure

More information

WITH ACTIVEWATCH EXPERT BACKED, DETECTION AND THREAT RESPONSE BENEFITS HOW THREAT MANAGER WORKS SOLUTION OVERVIEW:

WITH ACTIVEWATCH EXPERT BACKED, DETECTION AND THREAT RESPONSE BENEFITS HOW THREAT MANAGER WORKS SOLUTION OVERVIEW: SOLUTION OVERVIEW: ALERT LOGIC THREAT MANAGER WITH ACTIVEWATCH EXPERT BACKED, DETECTION AND THREAT RESPONSE Protecting your business assets and sensitive data requires regular vulnerability assessment,

More information

DELIVERING PERFORMANCE, SCALABILITY, AND AVAILABILITY ON THE SERVICENOW NONSTOP CLOUD

DELIVERING PERFORMANCE, SCALABILITY, AND AVAILABILITY ON THE SERVICENOW NONSTOP CLOUD DELIVERING PERFORMANCE, SCALABILITY, AND AVAILABILITY ON THE SERVICENOW NONSTOP CLOUD Overview Organizations, regardless of size, rely upon access to IT and business data and services for their continued

More information

Veritas Storage Foundation for Windows by Symantec

Veritas Storage Foundation for Windows by Symantec Veritas Storage Foundation for Windows by Symantec Advanced online storage management Veritas Storage Foundation 5.1 for Windows brings advanced online storage management to Microsoft Windows Server environments,

More information

Vendor: Citrix. Exam Code: 1Y Exam Name: Designing Citrix XenDesktop 7.6 Solutions. Version: Demo

Vendor: Citrix. Exam Code: 1Y Exam Name: Designing Citrix XenDesktop 7.6 Solutions. Version: Demo Vendor: Citrix Exam Code: 1Y0-401 Exam Name: Designing Citrix XenDesktop 7.6 Solutions Version: Demo DEMO QUESTION 1 Which option requires the fewest components to implement a fault-tolerant, load-balanced

More information

Enhancing VMware Horizon View with F5 Solutions

Enhancing VMware Horizon View with F5 Solutions Enhancing VMware Horizon View with F5 Solutions VMware Horizon View is the leading virtualization solution for delivering desktops as a managed service to a wide range of devices. F5 BIG-IP devices optimize

More information

ARCHITECTING WEB APPLICATIONS FOR THE CLOUD: DESIGN PRINCIPLES AND PRACTICAL GUIDANCE FOR AWS

ARCHITECTING WEB APPLICATIONS FOR THE CLOUD: DESIGN PRINCIPLES AND PRACTICAL GUIDANCE FOR AWS ARCHITECTING WEB APPLICATIONS FOR THE CLOUD: DESIGN PRINCIPLES AND PRACTICAL GUIDANCE FOR AWS Dr Adnene Guabtni, Senior Research Scientist, NICTA/Data61, CSIRO Adnene.Guabtni@csiro.au EC2 S3 ELB RDS AMI

More information

IBM Tivoli Access Manager for e-business V6.1.1 Implementation

IBM Tivoli Access Manager for e-business V6.1.1 Implementation 000-039 IBM Tivoli Access Manager for e-business V6.1.1 Implementation Version 14.23 Topic 1, Volume A QUESTION NO: 1 What is included in the high level configuration document when WebSEAL clustering must

More information

INTELLAFLEX. Packet Aggregation Switching Solutions

INTELLAFLEX. Packet Aggregation Switching Solutions INTELLAFLEX Packet Aggregation Switching Solutions APCON s scalable, high availability, network monitoring solutions increase tool efficiency for complete visibility of enterprise network traffic. Enterprise-Class

More information

DNS Anycast for High Availability and Performance

DNS Anycast for High Availability and Performance White Paper DNS Anycast for High Availability and Performance by Timothy Rooney Product management director BT Diamond IP DNS Anycast for High Availability and Performance By Tim Rooney, Director, Product

More information

Improving VDI with Scalable Infrastructure

Improving VDI with Scalable Infrastructure Improving VDI with Scalable Infrastructure As virtual desktop infrastructure (VDI) has become more prevalent, point solutions have emerged to address associated delivery issues. These solutions burden

More information

Models PDC/O5000 9i W2K Cluster Kit B24

Models PDC/O5000 9i W2K Cluster Kit B24 Overview Models PDC/O5000 9i W2K Cluster Kit 252478-B24 Introduction The HP Parallel Database Clusters (PDC) for Windows are multi-node shared storage clusters, specifically designed, tested and optimized

More information

Core Services for ediscovery Perfection

Core Services for ediscovery Perfection BEST-IN-CLASS DATA ENVIRONMENTS. Core Services for ediscovery Perfection MANAGE MANAGE IMPLEMENT IMPLEMENT ASSESS Core Services for ediscovery Perfection George Jon is an ediscovery infrastructure specialist

More information

IBM Internet Security Systems Proventia Management SiteProtector

IBM Internet Security Systems Proventia Management SiteProtector Supporting compliance and mitigating risk through centralized management of enterprise security devices IBM Internet Security Systems Proventia Management SiteProtector Highlights Reduces the costs and

More information

Features. HDX WAN optimization. QoS

Features. HDX WAN optimization. QoS May 2013 Citrix CloudBridge Accelerates, controls and optimizes applications to all locations: datacenter, branch offices, public and private clouds and mobile users Citrix CloudBridge provides a unified

More information

SQL Azure. Abhay Parekh Microsoft Corporation

SQL Azure. Abhay Parekh Microsoft Corporation SQL Azure By Abhay Parekh Microsoft Corporation Leverage this Presented by : - Abhay S. Parekh MSP & MSP Voice Program Representative, Microsoft Corporation. Before i begin Demo Let s understand SQL Azure

More information

Re-engineering the DNS One Resolver at a Time. Paul Wilson Director General APNIC channeling Geoff Huston Chief Scientist

Re-engineering the DNS One Resolver at a Time. Paul Wilson Director General APNIC channeling Geoff Huston Chief Scientist Re-engineering the DNS One Resolver at a Time Paul Wilson Director General APNIC channeling Geoff Huston Chief Scientist 1 In this presentation I ll talk about the DNS, and the root server infrastructure

More information

Securing Your Microsoft Azure Virtual Networks

Securing Your Microsoft Azure Virtual Networks Securing Your Microsoft Azure Virtual Networks IPS security for public cloud deployments It s no surprise that public cloud infrastructure has experienced fast adoption. It is quick and easy to spin up

More information

F5 and Infoblox DNS Integrated Architecture: Offering a Complete Scalable, Secure DNS Solution

F5 and Infoblox DNS Integrated Architecture: Offering a Complete Scalable, Secure DNS Solution F5 Technical Brief F5 and Infoblox DNS Integrated Architecture: Offering a Complete Scalable, Secure DNS Solution As market leaders in the application delivery market and DNS, DHCP, and IP Address Management

More information

Virtualizing Business- Critical Applications with Confidence TECHNICAL WHITE PAPER

Virtualizing Business- Critical Applications with Confidence TECHNICAL WHITE PAPER Virtualizing Business- Critical Applications with Confidence TECHNICAL WHITE PAPER Virtualizing Business-Critical Applications with Confidence Challenges Using Traditional High Availability Solutions Within

More information

Interoute Use Case. SQL 2016 Always On in Interoute VDC. Last updated 11 December 2017 ENGINEERED FOR THE AMBITIOUS

Interoute Use Case. SQL 2016 Always On in Interoute VDC. Last updated 11 December 2017 ENGINEERED FOR THE AMBITIOUS Interoute Use Case SQL 2016 Always On in Interoute VDC Last updated 11 December 2017 ENGINEERED FOR THE AMBITIOUS VERSION HISTORY Version Date Title Author 1 11 / 12 / 17 SQL 2016 Always On in Interoute

More information

1Y Designing Citrix XenDesktop 7.6 Solutions

1Y Designing Citrix XenDesktop 7.6 Solutions 1Y0-401 - Designing Citrix XenDesktop 7.6 Solutions 1. Scenario: CGE acquires a small energy company that is running MGMT, a proprietary 16-bit application. A Citrix Architect is tasked with deploying

More information

Introducing VMware Validated Designs for Software-Defined Data Center

Introducing VMware Validated Designs for Software-Defined Data Center Introducing VMware Validated Designs for Software-Defined Data Center VMware Validated Design 4.0 VMware Validated Design for Software-Defined Data Center 4.0 You can find the most up-to-date technical

More information

Veritas NetBackup Appliance Family OVERVIEW BROCHURE

Veritas NetBackup Appliance Family OVERVIEW BROCHURE Veritas NetBackup Appliance Family OVERVIEW BROCHURE Veritas NETBACKUP APPLIANCES Veritas understands the shifting needs of the data center and offers NetBackup Appliances as a way for customers to simplify

More information

Introducing VMware Validated Designs for Software-Defined Data Center

Introducing VMware Validated Designs for Software-Defined Data Center Introducing VMware Validated Designs for Software-Defined Data Center VMware Validated Design for Software-Defined Data Center 4.0 This document supports the version of each product listed and supports

More information

Deploying a Next-Generation IPS Infrastructure

Deploying a Next-Generation IPS Infrastructure Deploying a Next-Generation IPS Infrastructure Enterprises require intrusion prevention systems (IPSs) to protect their network against attacks. However, implementing an IPS involves challenges of scale

More information

VMware AirWatch Content Gateway Guide for Linux For Linux

VMware AirWatch Content Gateway Guide for Linux For Linux VMware AirWatch Content Gateway Guide for Linux For Linux Workspace ONE UEM v9.7 Have documentation feedback? Submit a Documentation Feedback support ticket using the Support Wizard on support.air-watch.com.

More information

Deploying a Next-Generation IPS Infrastructure

Deploying a Next-Generation IPS Infrastructure Deploying a Next-Generation IPS Infrastructure Enterprises require intrusion prevention systems (IPSs) to protect their network against attacks. However, implementing an IPS involves challenges of scale

More information

Securing Your Amazon Web Services Virtual Networks

Securing Your Amazon Web Services Virtual Networks Securing Your Amazon Web Services s IPS security for public cloud deployments It s no surprise that public cloud infrastructure has experienced fast adoption. It is quick and easy to spin up a workload,

More information

Symantec Network Security 7100 Series

Symantec Network Security 7100 Series Symantec Network Security 7100 Series Proactive intrusion prevention device protects against known and unknown attacks to secure critical networks transition can be accomplished transparent to any network

More information

WEBSCALE CONVERGED APPLICATION DELIVERY PLATFORM

WEBSCALE CONVERGED APPLICATION DELIVERY PLATFORM SECURITY ANALYTICS WEBSCALE CONVERGED APPLICATION DELIVERY PLATFORM BLAZING PERFORMANCE, HIGH AVAILABILITY AND ROBUST SECURITY FOR YOUR CRITICAL WEB APPLICATIONS OVERVIEW Webscale is a converged multi-cloud

More information

Introduction With the move to the digital enterprise, all organizations regulated or not, are required to provide customers and anonymous users alike

Introduction With the move to the digital enterprise, all organizations regulated or not, are required to provide customers and anonymous users alike Anonymous Application Access Product Brief Contents Introduction 1 The Safe-T Solution 1 How It Works 2-3 Capabilities 4 Benefits 4 List 5-11 Introduction With the move to the digital enterprise, all organizations

More information

Exam : Title : Security Solutions for Systems Engineers(SSSE) Version : Demo

Exam : Title : Security Solutions for Systems Engineers(SSSE) Version : Demo Exam : 642-565 Title : Security Solutions for Systems Engineers(SSSE) Version : Demo 1. SomeCompany, Ltd. wants to implement the the PCI Data Security Standard to protect sensitive cardholder information.

More information

Guide to Deploying NetScaler as an Active Directory Federation Services Proxy

Guide to Deploying NetScaler as an Active Directory Federation Services Proxy Deployment Guide Guide to Deploying NetScaler as an Active Directory Federation Services Proxy Enabling seamless authentication for Office 365 use cases Table of Contents Introduction 3 ADFS proxy deployment

More information

Data Security at Smart Assessor

Data Security at Smart Assessor Data Security at Smart Assessor Page 1 Contents Data Security...3 Hardware...3 Software...4 Data Backups...4 Personnel...5 Web Application Security...5 Encryption of web application traffic...5 User authentication...5

More information

SMARTARCHITECTURE TM : DNS-DHCP ARCHITECTURE MANAGEMENT

SMARTARCHITECTURE TM : DNS-DHCP ARCHITECTURE MANAGEMENT Datasheet SMARTARCHITECTURE TM : - ARCHITECTURE MANAGEMENT Go Beyond & Server Manage Architectures Even if & architecture configurations have been simplified with a GUI (Graphical User Interface), it is

More information

Security in Bomgar Remote Support

Security in Bomgar Remote Support Security in Bomgar Remote Support 2018 Bomgar Corporation. All rights reserved worldwide. BOMGAR and the BOMGAR logo are trademarks of Bomgar Corporation; other trademarks shown are the property of their

More information

The Privileged Appliance and Modules (TPAM) 1.0. Diagnostics and Troubleshooting Guide

The Privileged Appliance and Modules (TPAM) 1.0. Diagnostics and Troubleshooting Guide The Privileged Appliance and Modules (TPAM) 1.0 Guide Copyright 2017 One Identity LLC. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in

More information